Skip to main content

Cisco Unified Communications Manager XSS Vulnerability

A cross-site scripting (XSS) vulnerability has been found in the web-based management interface of Cisco Unified Communications Manager.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A cross-site scripting (XSS) vulnerability has been found in the web-based management interface of Cisco Unified Communications Manager.

Threat details

Using social engineering, an attacker can persuade a user to click a link that submits malicious input to the management interface. This exploit enables the attacker to execute arbitrary code within the interface or access sensitive information on the user's web browser.


Remediation advice

To avoid becoming compromised by this vulnerability, ensure that:

Remediation steps

Type Step
  • The software is updated to a fixed release.
  • A robust program of education and awareness training is delivered to users to ensure they don’t click on unknown links.

Last edited: 17 February 2020 12:40 pm